StackRadar

CVE-2026-102992

Critical

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,985 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env

Carried by container images the latest versions of 7 of 17,985 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
piscinanpm3.2.0, 4.9.2, 4.9.3, 5.1.4+2 more4.9.4, 5.3.28
OSV records
GHSA-67c8-pqhq-4rmx

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
piscina@3.2.0
4.9.4

Open the chart page →

42,281
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
piscina@5.1.4
5.3.2

Open the chart page →

8,324
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
piscina@4.9.2
4.9.4
sysnet4admin/colosseum-prm:log5802bfcd7fed
piscina@4.9.2
4.9.4

Open the chart page →

30,042
affinehelmforgeVerified publisher1.0.11 of 3See more

affine helmforge 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
piscina@5.2.0
5.3.2

Open the chart page →

4,683
its-mytabsstone0.3.01 of 1See more

its-mytabs stone 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
louislam/its-mytabs:1.7.02e478d3170bd
piscina@4.9.3
4.9.4

Open the chart page →

2,119
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
piscina@4.9.3
4.9.4

Open the chart page →

1,250
kibanawiremindVerified publisher8.5.241 of 2See more

kibana wiremind 8.5.24

1 of the 2 container images this version deploys carry CVE-2026-102992.

Container imageDigestPackageFixed in
library/kibana:8.19.2235544f1ff28a
piscina@5.3.1
5.3.2

Open the chart page →

1,665

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chocobozzz/peertube:v8.1.5052712130691
piscina@5.1.4
5.3.2
1
evershop/evershop:latestd0823576f91b
piscina@4.9.3
4.9.4
1
library/kibana:8.19.2235544f1ff28a
piscina@5.3.1
5.3.2
1
louislam/its-mytabs:1.7.02e478d3170bd
piscina@4.9.3
4.9.4
1
sysnet4admin/colosseum-cms:loge74b43c7f492
piscina@4.9.2
4.9.4
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
piscina@4.9.2
4.9.4
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
piscina@3.2.0
4.9.4
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
piscina@5.2.0
5.3.2
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.